Add RoboTwin 2.0 BYOF acceptance workflow - #451
Draft
timothy-le7 wants to merge 26 commits into
Draft
Conversation
timothy-le7
force-pushed
the
codex/top5-robotwin
branch
3 times, most recently
from
September 12, 2026 21:38
a1ea37f to
da5d6ac
Compare
timothy-le7
force-pushed
the
codex/top5-robotwin
branch
from
September 13, 2026 18:01
1712504 to
62f60cc
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
npa.workflow/v0.0.1spec.RoboTwin-Platform/RoboTwin@96c1feab536306b50c26af200044fcdf126e8904, its XPolicyLab submodulec37109c500be67d0dea6b36bf7337bbd26e763cd, RoboTwin2.0 assetsTianxingChen/RoboTwin2.0@785feb15aa4a4f532395ad2b1d2be5f28cb561ad, and CuRobo v0.7.8 sourceNVlabs/curobo@d64c4b005459db10c5dd867d8b30a87d5bda9bdbwithout silently upgrading any component.2.0-curobo-v0.7.8-rtfetch-unbuiltversion, is absent from accepted/public release inventories, and remains publication-quarantined.verdict: unknownandvalidation: pending-build, with matching not-routed/not-validated documentation.This PR remains a draft. It does not claim a built or pullable image, runtime/source/asset delivery, simulator success, generated output, public availability, or supported release.
Capability and workflow contract
The deferred hard-gate capability is
beat_block_hammer_successful_seed_replay_collection. A separately authorized live run must use the officialbeat_block_hammerbimanual task with thedemo_cleandata-collection configuration, discover and replay an actual successful seed through the real SAPIEN/Vulkan path, and emit native HDF5 plus decoded rendered video/frame artifacts.The exact proof remains
$NPA_SMOKE_OUTPUT_DIR/robotwin-smoke.json. It must bind the immutable source, asset, and CuRobo revisions; task/config/seed and successful task result; positive action and rendered-frame counts; HDF5/video hashes and sizes; Vulkan renderer evidence; exactly one observed RTX PRO 6000 Blackwell atsm_120; the pod-observed immutable image digest; and exit status zero. Imports, registration, or simulator startup alone are insufficient.The public YAML contains only sanitized placeholders. Its outer workflow task is CPU-only. The sole future inner accelerator declaration is exactly one STRICT
RTXPRO-6000-BLACKWELL-SERVER-EDITION; there is no B200 or fallback route. The manager-authorized source-staging and workload-output destinations remain distinct and never enter public plans, argv, logs, Git, or this PR. RoboTwin submit paths refuse before scheduler, image, network, registry, storage, or GPU effects without genuine authorization and authenticated staged-source byte proof; non-RoboTwin workflows retain their existing behavior.Six artifact boundaries and licensing
noncommercialcontainerization and technical validation/evaluation statement. No service, derivative, output, commercial, or redistribution right is inferred.sha256:281c5745f657873d78e5531fc5ba8575f46ab7769b94550ac99543f122679986, immutable Ubuntu snapshot20260912T000000Z, 75 exactmainbinary packages and their 75 copyright documents, 57 source packages/177 source artifacts, and a complete-empty zero-artifact Python runtime lock. CUDA, cuDNN, NVIDIA wheels, PyTorch CUDA, CuRobo, SAPIEN, MPLib, Warp, RoboTwin, and their build products are absent.The four unresolved human decisions remain CUDA delivery/use under the applicable EULA, cuDNN delivery/use under the applicable agreement, CuRobo v0.7.8 service/derivative/output boundaries beyond the bounded noncommercial evaluation, and aggregate RoboTwin asset/output treatment. Runtime fetch, credentials, a private registry, or a passing scanner cannot resolve those decisions.
Fail-closed controls
Exact current-head validation
All current-range Python evidence used repository CPython 3.12.14. The reviewed range is base/merge-base
c074fccb7836b22f5d19ef4f58ed7e76078e6c5ethrough head62f60cc61aad069c21a46aec6427c90e7971cf57: 26 ordinary commits, zero merges, and a 552,530-byte/61-section aggregate diff with SHA-256447c9a897e0473d850dd1de6d57a5102ff908294a2a57ccf773ae69d4c6e0a81.Fresh authenticated Claude Code and a distinct ephemeral read-only Codex verifier reviewed the exact base/head/merge-base and all 61 changed paths, 61 diff sections, and 26 ordinary commits. Both passed with 0 blocker/high/major/medium findings and 0 permission denials, writes, or subagents. Claude was provided only Read, Grep, and Glob. Historical denied/incomplete and pre-model review attempts remain preserved and are not counted as passes.
The five nonblocking review notes remain explicit:
registryfield reference; it cannot run under current gates and is not live evidence.Deferred gates
No solution source, SDK, runtime, weights, dataset, assets, cache, or output payload was downloaded. No image was built, tagged, pulled, scanned, or pushed. There is no OCI-byte inspection, SBOM, provenance, secret/vulnerability/payload/cache/data/history result, immutable image digest, private-registry pullability proof, anonymous public pull proof, Vulkan result, successful seed, native HDF5, video, or rendered frame.
Future work requires separate authorization and all four human decisions, followed by a complete exact runtime artifact lock; genuine manager-receipt recognition; exact provider/revision/terms access probes; authenticated source and asset bytes; reviewed positive native-content policy; trusted build and complete built-byte evidence; private exact-digest qualification on exactly one STRICT RTX PRO 6000 Blackwell; native policy/output validation; and only then public-development publication, catalog, and anonymous-pull gates. The candidate must never run its renderer on B200. The full 50-task sweep, policy training, and physical-robot deployment remain deferred.
The inherited fixed CRITICAL Perl CVEs in the pre-existing pinned Python slim-Trixie image used by a separate shared scan are not suppressed or waived here. That consuming image/workflow is outside this RoboTwin scope; any current-head CI result is reported separately and truthfully.
Agent-run data collection
Disabled: 0 of 2 required operator settings were present at the latest check. No write/readback verification was possible, no destination was inferred, and no episode was collected.